All templates
My Health Records Act · s75

My Health Record Data Breach Notification Procedure Template (Section 75)

The section 75 dual-notification procedure for a registered My Health Record provider organisation: an assessment guide for the three notifiable data breach categories, and a step-by-step process for notifying both the System Operator and the OAIC as soon as practicable. Includes the notification content checklist, the explicit rule against naming affected patients to the OAIC, and the boundary against the general Notifiable Data Breaches scheme, which this procedure does not replace.

My Health Records Act 2012My Health Records Rule 2016Privacy Act 19887 pages, Word format
30% off first month

All 73 templates included with ClinicComply

Subscribe to download the My Health Record Data Breach Notification Procedure and every other RACGP, NDIS, Privacy Act and WHS template, kept up to date for you.

Solo plan from
$79/month$99
Billed annually, AUD, GST inclusive
Use code AUG30 for 30% off your first month
  • All 73 templates
  • 30-day free trial
  • No credit card

What's in this template?

This My Health Record Data Breach Notification Procedure gives Australian healthcare practices the operational steps for section 75 of the My Health Records Act 2012: the mandatory duty to notify both the System Operator (the Australian Digital Health Agency) and the OAIC of a notifiable data breach involving the My Health Record system, as soon as practicable. It is built from the OAIC's Guide to Mandatory Data Breach Notification in the My Health Record System.

The template includes:

  1. The relationship to your general Data Breach Response Plan, stated as a direct comparison table so staff never mistake one duty for the other
  2. The three notifiable data breach categories under section 75, with a healthcare example for each
  3. An immediate containment checklist
  4. A 5-step dual notification procedure, with owners and timeframes
  5. The notification content checklist, including the explicit rule against naming affected patients to the OAIC
  6. Appendix A: a breach register for every incident assessed, whether or not it met the notification threshold

Editable placeholder fields

  • {{practice_name}}, {{hpi_o}}
  • {{responsible_officer}}, {{responsible_officer_email}}
  • {{privacy_officer}}, {{it_support_contact}}
  • {{effective_date}}, {{next_review_date}}, {{approved_by}}

This is not your general data breach plan

This is the single most important thing to understand about this document: section 75 is a separate legal duty from the Notifiable Data Breaches scheme, and having a Data Breach Response Plan does not discharge it.

This procedure (My Health Records Act, s75)Data Breach Response Plan (Privacy Act, NDB scheme)
Applies toAny registered My Health Record provider organisation, for incidents involving the My Health Record systemAny APP entity, for an eligible data breach of personal information generally
ThresholdA breach or possible breach. No serious harm testAn eligible data breach: likely to result in serious harm
Who is notifiedThe System Operator AND the OAICAffected individuals AND the OAIC
TimeframeAs soon as practicableAs soon as practicable, generally within 30 days of an assessment

The threshold here is deliberately lower than the general scheme. A possible breach is enough to trigger notification, and there is no serious harm test to clear first. That is why a practice needs this procedure as a fast, separate trigger rather than folding My Health Record incidents into the general plan and hoping the same steps cover both.

In practice, many incidents trigger both procedures at once. A staff member inappropriately viewing a patient's My Health Record, for example, is assessed under this procedure first because the notification duty is faster, and the Privacy Officer separately runs the general NDB assessment in parallel. Both notifications go out. Neither replaces the other.

What the law actually requires

Section 75 defines a notifiable data breach across three categories, and any one of them is enough on its own:

  1. Unauthorised collection, use or disclosure: a person has, or may have, contravened the Act in a way involving unauthorised collection, use or disclosure of health information in a My Health Record.
  2. System compromise: an event has, or may have, occurred that compromises, or may compromise, the security or integrity of the My Health Record system.
  3. Circumstantial threat: circumstances have, or may have, arisen that compromise, or may compromise, the system's security or integrity.

Categories 2 and 3 do not require an actual contravention of the Act. A leaked password list containing the practice's My Health Record login, or a NASH PKI certificate found on an unattended device, can each be a notifiable event on its own, before anyone has actually misused anything.

Once identified, both the System Operator and the OAIC must be told as soon as practicable. The OAIC's guidance is explicit that reporting should not wait for containment to be finished or for every fact to be confirmed. An incomplete notification, followed up with more detail as it becomes available, is the expected pattern, not a failure to notify properly the first time.

How to customise this template

  1. Download the Word document and replace every {{placeholder}} with your details.
  2. Confirm your Responsible Officer, the person named to the Australian Digital Health Agency, matches the person named in your Security and Access Policy.
  3. Brief staff on Section 4, the three notifiable categories, so a possible breach is reported the day it is noticed rather than sat on while someone tries to confirm it.
  4. Confirm the relationship in Section 3 is understood by whoever leads your general breach response, so a My Health Record incident is never run through only one of the two procedures.
  5. Keep the notification content checklist in Section 7 handy, and note the rule against naming affected patients in the OAIC notification.
  6. Review every two years, or sooner after any incident handled under it.

Related templates and tools

Frequently asked questions

Do we still need a general Data Breach Response Plan if we have this procedure?

Yes. This procedure only covers the section 75 duty to notify the System Operator and the OAIC about a My Health Record incident. It does not cover notifying affected patients, which is a separate obligation under the general Notifiable Data Breaches scheme, and it does not cover a breach that has nothing to do with the My Health Record system. Most practices need both documents.

What counts as a "possible" breach under section 75?

Any of the three categories in the Act: a possible unauthorised collection, use or disclosure of health information in a My Health Record, a possible compromise of the system's security or integrity, or circumstances that may compromise it. The word "may" is doing real work here. You do not need to confirm the breach actually happened or that harm resulted before the notification duty applies.

Who do we notify: the System Operator, the OAIC, or both?

Both, for a registered healthcare provider organisation. The System Operator is the Australian Digital Health Agency. Some entity types, such as state and territory authorities, notify the System Operator only, but a general practice or allied health provider notifies both.

How fast does this have to happen?

As soon as practicable. The OAIC's guidance does not set a fixed number of days, but it is explicit that notification should not be delayed while containment efforts are still under way, and that an initial notification can be updated with more information later. Treat "as soon as practicable" as the same working session the incident is discovered in, not the next business day.

Can we name the affected patient in the notification to the OAIC?

No. The template's notification checklist carries this as an explicit rule: identify affected people internally by record or reference number, and do not include their identities in what is sent to the OAIC.

Is there a penalty for not reporting?

Yes, civil penalties apply to reporting entities that fail to comply with the section 75 duty. The System Operator itself faces no penalty for failing to pass a breach on to the OAIC, but the OAIC can investigate where it suspects a breach has gone unreported, which is a separate exposure for the practice if its own notification never happened.

Does every incident go in the breach register, or only the ones we report?

Every incident assessed under Section 4 of this procedure, whether or not it met the notification threshold. That record is what the System Operator or the OAIC will expect to see if they ask how the practice handles potential breaches, and it is also the evidence that near-misses are being tracked, not just confirmed incidents.

30-day free trial, no credit card

Be the practice the assessor compliments.

Set up your frameworks this weekend. Walk into your next visit with every criterion linked to current evidence, and nothing left to chase.

No credit card required
Australian data residency (Sydney)
Cancel anytime